EDBT 2026 Demo / reviewers in the wild / expert
Leonardo Aniello
dblp:32/10081
· DBLP profile ↗
16ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0003-2886-8445ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 first-author · 3 since 2021Systems, architecture and hardware · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 3 · 2 since 2021Theory of computation · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Software supply chain: A taxonomy of attacks, mitigations and risk assessment strategiesabstractThe software product is a source of cyber-attacks that target organizations by using their software supply chain (SSC) as a distribution vector. As the reliance of software projects on open-source or proprietary modules is increasing drastically, SSC is becoming more and more critical and, therefore, has attracted the interest of cyber attackers. While existing studies primarily focus on software supply chain attacks’ prevention and detection methods, there is a need for a broad overview of attacks and comprehensive risk assessment for software supply chain security. This study conducts a systematic literature review to fill this gap. By analyzing 96 papers published between 2015-2023, we identified 19 distinct SSC attacks, including 6 novel attacks highlighted in recent studies. Additionally, we developed 25 specific security controls and established a precisely mapped taxonomy that transparently links each control to one or more specific attacks. By establishing this relationship, we demonstrate how SSC security controls are strategically designed to counteract specific attack vectors. Furthermore, we emphasize the role of risk assessment as a foundational step in understanding and prioritizing these vulnerabilities. This study introduces a risk assessment methodology tailored to software supply chain environments, focusing on identifying vulnerabilities in software components, dependencies, and suppliers. The proposed methodology enables organizations to systematically prioritize threats and implement appropriate mitigation strategies. Betul Gokkaya, Leonardo Aniello, Basel Halak |
J. Inf. Secur. Appl. | 2 |
| 2025 | Uncovering Evaluation Bias in Node Attachment Strategies for the Lightning NetworkabstractThe Lightning Network (LN) is a peer-to-peer network composed of nodes and channels, operating as an offchain payment protocol on top of the Bitcoin blockchain. A newly joining node needs to determine which existing node(s) to establish channel(s) with. This decision is guided by an attachment strategy, which is an algorithm that strategically recommends which Lightning Network node(s) to connect to based on predefined metrics and optimization goals. Current research on Lightning Network attachment strategies focuses primarily on evaluating and enhancing performance, such as payment success rate and transaction fees, as well as influence on network centralisation. However, the evaluation methods commonly used in the literature display two shortcomings: (i) they often rely on a single network topology snapshot, and/or (ii) their simulations are not based on realistic models (e.g., neglecting the network's evolution over time). In this paper, we demonstrate that these two shortcomings can generate biased results, potentially leading to non-generalisable and skewed evaluations of attachment strategies. In our evaluation, six state-of-the-art attachment strategies are evaluated using diverse real-world snapshots of the Lightning Network and a realistic network evolution model based on an estimated churn rate. The experimental results show significant differences from those reported in the literature, confirming that their evaluation methods are subject to bias. For instance, k-median, previously noted for strong fee revenue, sees its routing share drop from 3 % to 0.2 % in a different snapshot; k-center shifts from best to worst in long-term fee reduction under churn; random strategy unexpectedly outperforms in reducing fees and promoting decentralization; and computationally intensive strategies like k-median become impractical on larger topologies, emphasizing the need for diverse, realistic evaluation settings. Asma Almosa, Leonardo Aniello, Boojoong Kang |
SRDS | 2 |
| 2025 | Developing Safe Exception Recovery Mechanisms for CHERI Capability Hardware Using UML-B Formal Analysis
Colin F. Snook, Asieh Salehi Fathabadi, Thai Son Hoang, Robert Thorburn, Michael J. Butler, Leonardo Aniello, Vladimiro Sassone |
ABZ | 6 |
| 2024 | ScaNeF-IoT: Scalable Network Fingerprinting for IoT DeviceabstractRecognising IoT devices through network fingerprinting contributes to enhancing the security of IoT networks and supporting forensic activities. Machine learning techniques have been extensively utilised in the literature to optimise IoT fingerprinting accuracy. Given the rapid proliferation of new IoT devices, a current challenge in this field is around how to make IoT fingerprinting scalable, which involves efficiently updating the used machine learning model to enable the recognition of new IoT devices. Some approaches have been proposed to achieve scalability, but they all suffer from limitations like large memory requirements to store training data and accuracy decrease for older devices. Tadani Nasser Alyahya, Leonardo Aniello, Vladimiro Sassone |
ARES | 2 |
| 2024 | MANET-Rank: A Framework for Defence Protocols against Packet Dropping Attacks in MANETsabstractFlying ad hoc networks (FANETs) are collections of Unmanned Aerial Vehicles (UAVs) or nodes which deliver network services to areas lacking fixed infrastructure. The protocols controlling the flow of data in these ad hoc networks are prone to cyber attacks. In this paper, we consider cyber attacks in the form of probabilistic packet dropping or grey hole attacks which are executed by compromised nodes within the network. The defence protocols used to thwart this attack are usually evaluated in restricted environments with a low range of packet dropping attacks. To remedy this, we propose a new competitive evaluation framework, MANET-Rank, which uses empirical game theoretic analysis and bootstrapping to assess the effectiveness of defence protocols in ad hoc networks. Specifically, game theory is used to strategically assess the most effective protocol whilst bootstrapping generates an effective ranking metric from a small number of simulations. To assess the effectiveness of MANET-Rank, we conduct a comparative analysis of two previously proposed protocols by comparing the results of MANET-Rank and those generated by established evaluation methods. As a result, we demonstrate that MANET-Rank yields superior conclusions. Charles Hutchins, Leonardo Aniello, Enrico H. Gerding, Basel Halak |
NOMS | 2 |
| 2024 | Designing Exception Handling Using Event-B
Asieh Salehi Fathabadi, Colin F. Snook, Thai Son Hoang, Robert Thorburn, Michael J. Butler, Leonardo Aniello, Vladimiro Sassone |
ABZ | 6 |
| 2019 | Survey of machine learning techniques for malware analysis
Daniele Ucci, Leonardo Aniello, Roberto Baldoni |
Comput. Secur. | 2 |
| 2019 | PASCAL: An architecture for proactive auto-scaling of distributed services
Federico Lombardi, Andrea Muti, Leonardo Aniello, Roberto Baldoni, Silvia Bonomi, Leonardo Querzoni |
Future Gener. Comput. Syst. | 3 |
| 2018 | Elastic Symbiotic Scaling of Operators and Resources in Stream Processing SystemsabstractDistributed stream processing frameworks are designed to perform continuous computation on possibly unbounded data streams whose rates can change over time. Devising solutions to make such systems elastically scale is a fundamental goal to achieve desired performance and cut costs caused by resource over-provisioning. These systems can be scaled along two dimensions: the operator parallelism and the number of resources. In this paper, we show how these two dimensions, as two symbiotic entities, are independent but must mutually interact for the global benefit of the system. On the basis of this observation, we propose a fine-grained model for estimating the resource utilization of a stream processing application that enables the independent scaling of operators and resources. A simple, yet effective, combined management of the two dimensions allows us to propose ELYSIUM, a novel elastic scaling approach that provides efficient resource utilization. We implemented the proposed approach within Apache Storm and tested it by running two real-world applications with different input load curves. The outcomes backup our claims showing that the proposed symbiotic management outperforms elastic scaling strategies where operators and resources are jointly scaled. Federico Lombardi, Leonardo Aniello, Silvia Bonomi, Leonardo Querzoni |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2017 | Share a pie?: Privacy-Preserving Knowledge Base Export through Count-min SketchesabstractKnowledge base (KB) sharing among parties has been proven to be beneficial in several scenarios. However such sharing can arise considerable privacy concerns depending on the sensitivity of the information stored in each party's KB. In this paper, we focus on the problem of exporting a (part of a) KB of a party towards a receiving one. We introduce a novel solution that enables parties to export data in a privacy-preserving fashion, based on a probabilistic data structure, namely the \emph{count-min sketch}. With this data structure, KBs can be exported in the form of key-value stores and inserted into a set of count-min sketches, where keys can be sensitive and values are counters. Count-min sketches can be tuned to achieve a given key collision probability, which enables a party to deny having certain keys in its own KB, and thus to preserve its privacy. We also introduce a metric, the γ-deniability (novel for count-min sketches), to measure the privacy level obtainable with a count-min sketch. Furthermore, since the value associated to a key can expose to linkage attacks, noise can be added to a count-min sketch to ensure controlled error on retrieved values. Key collisions and noise alter the values contained in the exported KB, and can affect negatively the accuracy of a computation performed on the exported KB. We explore the tradeoff between privacy preservation and computation accuracy by experimental evaluations in two scenarios related to malware detection. Daniele Ucci, Leonardo Aniello, Roberto Baldoni |
CODASPY | 2 |
| 2017 | The goods, the bads and the uglies: Supporting decisions in malware detection through visual analyticsabstractMalware associated with Web downloads is responsible for many attacks trying to execute malicious code on a remote machine. Web browsers are protected by anti-malware utilities that try to distinguish between good downloads and bad downloads, blocking the bad ones and alerting the user. In order to cope with the uncertainty of such a process, very often the final decision is made using suitable thresholds, giving rise to a 3 categories classification: good downloads, bad downloads, and “in the middle” downloads (i.e., the uglies). In this situation, it is possible to involve the user (e.g., the security manager) in the decision loop, presenting him with the details of the decision process in a way he can either be more confident about the system decisions or he can refine what has been done automatically, e.g., promoting an ugly download to a good one. The paper addresses this problem presenting a visual analytics solution supporting the analysis of the classification system presented in AMICO [24], providing the user with a better understanding of the classification decisions and the possibility of changing the classification results. A prototype is available at: http://awareserver.dis.uniroma1.it:11768/malvis/. Marco Angelini, Leonardo Aniello, Simone Lenti, Giuseppe Santucci, Daniele Ucci |
VizSEC | 2 |
| 2016 | Automatic Invariant Selection for Online Anomaly Detection
Leonardo Aniello, Claudio Ciccotelli, Marcello Cinque, Flavio Frattini, Leonardo Querzoni, Stefano Russo 0001 |
SAFECOMP | 1 |
| 2015 | NIRVANA: A Non-intrusive Black-Box Monitoring Framework for Rack-Level Fault DetectionabstractMany organizations today still manage mid or large in-house data centers that require very expensive maintenance efforts, including fault detection. Common monitoring frameworks used to quickly detect faults are complex to deploy/maintain, expensive, and intrusive as they require the installation of probes on monitored hw/sw to collect raw data. Such intrusiveness can be problematic as it imposes installation/management overhead and may interfere with security/privacy policies. In this paper we introduce NIRVANA, a novel monitoring system for fault detection that works at rack-level and is (i) non-intrusive, i.e., it does not require the installation of software probes on the hosts to be monitored and (ii) black-box, i.e., agnostic with respect to monitored applications. At the core of our solution lies the observation that aggregated features that can be monitored at rack-level in a non-intrusive and black-box way, show predictable behaviors while the system works in both fault-free and faulty states, it is therefore possible to detect and identify faults by monitoring and analyzing any perturbations to these behaviors. An extensive experimental evaluation shows that non-intrusiveness does not significantly hamper the fault detection capabilities of the monitoring system, thus validating our approach. Claudio Ciccotelli, Leonardo Aniello, Federico Lombardi, Luca Montanari, Leonardo Querzoni, Roberto Baldoni |
PRDC | 2 |
| 2015 | High frequency batch-oriented computations over large sliding time windows
Leonardo Aniello, Leonardo Querzoni, Roberto Baldoni |
Future Gener. Comput. Syst. | 1 |
| 2014 | An event-based platform for collaborative threats detection and monitoring
Giorgia Lodi, Leonardo Aniello, Giuseppe Antonio Di Luna, Roberto Baldoni |
Inf. Syst. | 2 |
| 2011 | A Collaborative Event Processing System for Protection of Critical Infrastructures from Cyber Attacks
Leonardo Aniello, Giuseppe Antonio Di Luna, Giorgia Lodi, Roberto Baldoni |
SAFECOMP | 1 |